CVE-2010-1039

UnknownEPSS 20.17%

Last modified

CVE-2010-1039 is a vulnerability of currently unknown severity. Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.. EPSS estimates a 20.17% chance of exploitation in the next 30 days.

Description

Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

Metrics

EPSS Probability
20.17%

97.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
HpNfs\/Oncplus<= b.11.31_09
IbmAix<= 5.3
IbmAix1.2.1
IbmAix1.3
IbmAix2.2.1
IbmAix3.1
IbmAix3.2
IbmAix3.2.0
IbmAix3.2.4
IbmAix3.2.5
IbmAix4
IbmAix4.0
IbmAix4.1
IbmAix4.1.1
IbmAix4.1.2
IbmAix4.1.3
IbmAix4.1.4
IbmAix4.1.5
IbmAix4.2
IbmAix4.2.0
IbmAix4.2.1
IbmAix4.2.1.12
IbmAix4.3
IbmAix4.3.0
IbmAix4.3.1
IbmAix4.3.2
IbmAix4.3.3
IbmAix5.1
IbmAix5.1.0.10
IbmAix5.1l
IbmAix5.2
IbmAix5.2.0
IbmAix5.2.0.50
IbmAix5.2.0.54
IbmAix5.2.2
IbmAix5.2_l
IbmAix6.1
IbmAix430
IbmVios<= 1.5
IbmVios1.4
IbmVios2.1
SgiIrix6.5

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-1039?
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
How severe is CVE-2010-1039?
Severity scoring for CVE-2010-1039 is pending analysis. The EPSS model estimates a 20.17% probability of exploitation in the next 30 days.
How do I fix CVE-2010-1039?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-1039?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST